Redhat
17,638 known vulnerabilities
Top Products
A flaw was found in wildfly. The JBoss EJB client has publicly accessible privileged actions which may lead to informati
A flaw was found in OpenJPEG’s encoder in the opj_dwt_calc_explicit_stepsizes() function. This flaw allows an attacker w
A flaw was found in keycloak. Directories can be created prior to the Java process creating them in the temporary direct
A flaw was found in the hivex library in versions before 1.3.20. It is caused due to a lack of bounds check within the h
A flaw was found in tripleo-ansible version as shipped in Red Hat Openstack 16.1. The Ansible log file is readable to al
An out-of-bounds (OOB) memory write flaw was found in list_devices in drivers/md/dm-ioctl.c in the Multi-device driver m
A heap buffer overflow was found in the floppy disk emulator of QEMU up to 6.0.0 (including). It could occur in fdctrl_t
A flaw was found in the Linux kernel in versions before 5.12. The value of internal.ndata, in the KVM API, is mapped to
A flaw was found in samba. The Samba smbd file server must map Windows group identities (SIDs) into unix group ids (gids
NVIDIA vGPU driver contains a vulnerability in the Virtual GPU Manager (vGPU plugin), which could allow an attacker to r
NVIDIA vGPU driver contains a vulnerability in the Virtual GPU Manager (vGPU plugin) where it allows guests to control u
NVIDIA vGPU driver contains a vulnerability in the Virtual GPU Manager (vGPU plugin), where there is the potential to wr
NVIDIA vGPU driver contains a vulnerability in the guest kernel mode driver and Virtual GPU Manager (vGPU plugin), in wh
NVIDIA vGPU software contains a vulnerability in the guest kernel mode driver and Virtual GPU Manager (vGPU plugin), in
NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager (vGPU plugin), in which an input length is not
NVIDIA vGPU software contains a vulnerability in the guest kernel mode driver and Virtual GPU manager (vGPU plugin), in
NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager (vGPU plugin), in which certain input data is n
A flaw was found in the Ansible Engine 2.9.18, where sensitive info is not masked by default and is not protected by the
A flaw was found in xorg-x11-server in versions before 1.20.11. An integer underflow can occur in xserver which can lead
A flaw was found in cifs-utils in versions before 6.13. A user when mounting a krb5 CIFS file system from within a conta
A flaw was found in libtpms in versions before 0.8.0. The TPM 2 implementation returns 2048 bit keys with ~1984 bit stre
GStreamer before 1.18.4 might cause heap corruption when parsing certain malformed Matroska files.
GStreamer before 1.18.4 might access already-freed memory in error code paths when demuxing certain malformed Matroska f
A security vulnerability in HPE IceWall SSO Domain Gateway Option (Dgfw) module version 10.0 on RHEL 5/6/7, version 10.0
An authentication flaw was found in ceph in versions before 14.2.20. When the monitor handles CEPHX_GET_AUTH_SESSION_KEY
A flaw was found in Exiv2 in versions before and including 0.27.4-RC1. Improper input validation of the rawData.size pro
A flaw was found in dnsmasq in versions before 2.85. When configured to use a specific server for a given network interf
A flaw was found in Red Hat Satellite in tfm-rubygem-foreman_azure_rm in versions before 2.2.0. A credential leak was id
A flaw was found in Nettle in versions before 3.7.2, where several Nettle signature verification functions (GOST DSA, ED
A flaw was found in several ansible modules, where parameters containing credentials, such as secrets, were being logged
A deadlock vulnerability was found in 'github.com/containers/storage' in versions before 1.28.1. When a container image
An information leak was discovered in postgresql in versions before 13.2, before 12.6 and before 11.11. A user having UP
A flaw was found in RESTEasy in all versions of RESTEasy up to 4.6.0.Final. The endpoint class and method names are retu
A flaw was found in RPM's signature check functionality when reading a package file. This flaw allows an attacker who ca
There is an open race window when writing output in the following utilities in GNU binutils version 2.35 and earlier:ar,
When binding against a DN during authentication, the reply from 389-ds-base will be different whether the DN exists or n
A flaw possibility of race condition and incorrect initialization of the process id was found in the Linux kernel child/
A flaw was found in libmicrohttpd. A missing bounds check in the post_process_urlencoded function leads to a buffer over
A flaw was found in libtpms in versions before 0.8.2. The commonly used integration of libtpms with OpenSSL contained a
A NULL pointer dereference flaw was found in the way Jasper versions before 2.0.27 handled component references in the J
An insecure modification vulnerability in the /etc/passwd file was found in the operator-framework/hadoop as shipped in
An insecure modification vulnerability in the /etc/passwd file was found in the operator-framework/hive as shipped in Re
An insecure modification vulnerability in the /etc/passwd file was found in the operator-framework/presto as shipped in
An insecure modification vulnerability in the /etc/passwd file was found in the openshift/ansible-service-broker as ship
An insecure modification vulnerability in the /etc/passwd file was found in the container operator-framework/operator-me
The patch for CVE-2020-17380/CVE-2020-25085 was found to be ineffective, thus making QEMU vulnerable to the out-of-bound
A flaw was found in Undertow when using Remoting as shipped in Red Hat Jboss EAP before version 7.2.4. A memory leak in
An infinite loop in SMLLexer in Pygments versions 1.5 to 2.7.3 may lead to denial of service when performing syntax high
A flaw was found in keycloak. The new account console in keycloak can allow malicious code to be executed using the refe
A flaw was found in atomic-openshift of openshift-4.2 where the basic-user RABC role in OpenShift Container Platform doe
Frequently Asked Questions
How many CVEs affect Redhat?
Redhat has 17,638 CVE records in our database, including 1817 critical and 6954 high severity vulnerabilities. 43 of these are listed in CISA's Known Exploited Vulnerabilities catalog.
What are the most severe Redhat vulnerabilities?
Redhat has 1817 critical severity (CVSS 9.0+) and 6954 high severity (CVSS 7.0-8.9) vulnerabilities. 43 vulnerabilities are confirmed as actively exploited in the wild.
How can I scan for Redhat vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Redhat products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Redhat Vulnerabilities
CyberStrike scans your infrastructure for Redhat vulnerabilities and provides real-time remediation guidance.
Get Started